• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

Mobile ID World

Mobile ID World

Identification Revolution

  • Mobile ID
    • What Is Mobile ID?
    • Identity Associations
    • Premier Partners
    • FAQ
  • News
  • Solutions
    • Behavioral
    • Facial Recognition
    • Fingerprint Biometrics
    • Iris Biometrics
    • Second Factor
    • Smart Cards
    • Smartphones
    • Vital
    • Voice
    • Wearable Tech
    • Other
  • Applications
    • Access Control
    • Cloud Technology
    • Commerce
    • Enterprise
    • Healthcare
    • Identification
    • Internet of Things
    • Law Enforcement
    • Strong Online Authentication
  • Exclusive
    • Interviews
    • Featured Articles
    • Podcasts
  • Companies
  • Events

Buguroo Sounds Alarm About Malicious Apps in Google Play Store

January 14, 2020

Buguroo Sounds Alarm About Malicious Apps in Google Play Store

Buguroo is warning consumers about three malicious applications that are currently available through Google Play. All three applications take advantage of the Android Binder vulnerability, and were first uncovered by Trend Micro researchers Ecular Xu and Joseph Chen.

The offending applications are Camero, callCam, and FileCrypt Manager, all three of which should obviously be avoided. The first two are masquerading as photo editing tools, while the third is pretending to be an Android file manager.

In truth, they are designed to obtain root privileges on any device that downloads the apps in question. In plain terms, that means that a hacker will have full control of the device, and will have access to any and all passwords and personal information that has been stored on it. The process does not require any additional permissions once the app has been installed, so the victim is usually not aware that their device has been hacked.

So how does it work? The technical details are complicated, but the malware attacks the Android’s Binder component, which is used to facilitate communication between two processes within the same application. The hack tricks the Binder into acknowledging a section of malicious code, and convinces it to carry out that code in a way that bypasses the permissions granted to the original application.

Camero serves as a delivery system that will download the DEX file that contains the malicious code, and is effective against Pixel 2, Pixel 2 XL, Nokia 3, LG V20, Oppo F9, and Redmi 6A devices. FileCrypt Manager uses false overlays to trick the user into installing callCam, which hides its own icon as it starts gathering data.

The three apps are particularly insidious because they seem to be legitimate apps that have theoretically been vetted like any other application available through Google play, making it more likely that unsuspecting consumers will voluntarily choose to install them. That also sets them apart from the Coybot Trojan that Buguroo warned against in December, which is easier to stop with security measures like behavioral analytics and two-step authentication.  

Filed Under: Industry News Tagged With: Android, Buguroo, cybersecurity, device hacking, device security, Google Play, hack attacks, malicious applications, malicious apps, mobile security

Related News & Articles

Riyad Bank Targets Young Saudis with Gemalto Payment Wristbands

Precise Biometrics Sets Date and Agenda for AGM

Biometric Payments Specialist Looks to Extend Reach Via Mastercard Payment Gateway Services

Primary Sidebar

Register For the Next Virtual Identity Summit

Register now!

Tweets

Sponsored Links

facetec logo

FaceTec’s patented, industry-leading 3D Face Authentication software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ make trusted, remote identity verification finally possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for Liveness and 3D Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

FACEPHI is a global leader in Facial Recognition technology and in Mobile Biometrics technologies. With a strong concentration in the financial sector, FacePhi’s product is rapidly becoming a service used by banks all over the world. Its implementation doesn’t just save money, it is also a way to attract clients and build loyalty, while increasing the security of transactions for both the customer and the business. To learn more about FacePhi, visit https://www.facephi.com/en/

Recent Posts

  • Kenya’s New President Pushes for Digital ID By Year’s End
  • MDL, Digital ID Gain Momentum in State Efforts
  • Brazil-based Selfie Onboarding Startup Reports 250% Sales Jump, Global Expansion
  • ‘All Partners Remain Committed’ to Digital Travel ID Project: Transport Canada
  • North Carolina DMV Seeks Political Support for MDL

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2023 MobileIDWorld